logo

RedSun: Windows 0day when Defender becomes the attacker

ID: 9623672c-1a71-510f-9718-3c2c2f5fe172

STIX ID: report--9623672c-1a71-510f-9718-3c2c2f5fe172

Feed Name: CloudSEK Blog

Threat Score
80/100

Date Published: 2026-04-17

Date Updated: 2026-05-12

...
...

## Executive summary This report describes "RedSun", a reliable local privilege escalation exploit that leverages a missing reparse-point validation in Windows Defender's remediation path (MpSvc.dll / MsMpEng.exe). By combining Cloud Files placeholders, a batch OPLOCK timing window, VSS snapshot detection, and a junction point swap, an unprivileged user can cause Defender to write an attacker-controlled binary into C:\Windows\System32 and trigger it via the Storage Tiers COM server, yielding SYSTEM-level code execution on fully patched Windows systems. The document includes a detailed code-path analysis, detection/mitigation recommendations, and notes that no patch was available at time of writing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.